1//===-- sanitizer_common_interceptors_ioctl.inc -----------------*- C++ -*-===// 2// 3// This file is distributed under the University of Illinois Open Source 4// License. See LICENSE.TXT for details. 5// 6//===----------------------------------------------------------------------===// 7// 8// Ioctl handling in common sanitizer interceptors. 9//===----------------------------------------------------------------------===// 10 11#include "sanitizer_flags.h" 12 13struct ioctl_desc { 14 unsigned req; 15 // FIXME: support read+write arguments. Those are currently marked as WRITE. 16 enum { 17 NONE, 18 READ, 19 WRITE, 20 CUSTOM 21 } type : 2; 22 unsigned size : 30; 23 const char* name; 24}; 25 26const unsigned ioctl_table_max = 500; 27static ioctl_desc ioctl_table[ioctl_table_max]; 28static unsigned ioctl_table_size = 0; 29 30// This can not be declared as a global, because references to struct_*_sz 31// require a global initializer. And this table must be available before global 32// initializers are run. 33static void ioctl_table_fill() { 34#define _(rq, tp, sz) \ 35 if (IOCTL_##rq != IOCTL_NOT_PRESENT) { \ 36 CHECK(ioctl_table_size < ioctl_table_max); \ 37 ioctl_table[ioctl_table_size].req = IOCTL_##rq; \ 38 ioctl_table[ioctl_table_size].type = ioctl_desc::tp; \ 39 ioctl_table[ioctl_table_size].size = sz; \ 40 ioctl_table[ioctl_table_size].name = #rq; \ 41 ++ioctl_table_size; \ 42 } 43 44 _(FIOASYNC, READ, sizeof(int)); 45 _(FIOCLEX, NONE, 0); 46 _(FIOGETOWN, WRITE, sizeof(int)); 47 _(FIONBIO, READ, sizeof(int)); 48 _(FIONCLEX, NONE, 0); 49 _(FIOSETOWN, READ, sizeof(int)); 50 _(SIOCADDMULTI, READ, struct_ifreq_sz); 51 _(SIOCATMARK, WRITE, sizeof(int)); 52 _(SIOCDELMULTI, READ, struct_ifreq_sz); 53 _(SIOCGIFADDR, WRITE, struct_ifreq_sz); 54 _(SIOCGIFBRDADDR, WRITE, struct_ifreq_sz); 55 _(SIOCGIFCONF, CUSTOM, 0); 56 _(SIOCGIFDSTADDR, WRITE, struct_ifreq_sz); 57 _(SIOCGIFFLAGS, WRITE, struct_ifreq_sz); 58 _(SIOCGIFMETRIC, WRITE, struct_ifreq_sz); 59 _(SIOCGIFMTU, WRITE, struct_ifreq_sz); 60 _(SIOCGIFNETMASK, WRITE, struct_ifreq_sz); 61 _(SIOCGPGRP, WRITE, sizeof(int)); 62 _(SIOCSIFADDR, READ, struct_ifreq_sz); 63 _(SIOCSIFBRDADDR, READ, struct_ifreq_sz); 64 _(SIOCSIFDSTADDR, READ, struct_ifreq_sz); 65 _(SIOCSIFFLAGS, READ, struct_ifreq_sz); 66 _(SIOCSIFMETRIC, READ, struct_ifreq_sz); 67 _(SIOCSIFMTU, READ, struct_ifreq_sz); 68 _(SIOCSIFNETMASK, READ, struct_ifreq_sz); 69 _(SIOCSPGRP, READ, sizeof(int)); 70 _(TIOCCONS, NONE, 0); 71 _(TIOCEXCL, NONE, 0); 72 _(TIOCGETD, WRITE, sizeof(int)); 73 _(TIOCGPGRP, WRITE, pid_t_sz); 74 _(TIOCGWINSZ, WRITE, struct_winsize_sz); 75 _(TIOCMBIC, READ, sizeof(int)); 76 _(TIOCMBIS, READ, sizeof(int)); 77 _(TIOCMGET, WRITE, sizeof(int)); 78 _(TIOCMSET, READ, sizeof(int)); 79 _(TIOCNOTTY, NONE, 0); 80 _(TIOCNXCL, NONE, 0); 81 _(TIOCOUTQ, WRITE, sizeof(int)); 82 _(TIOCPKT, READ, sizeof(int)); 83 _(TIOCSCTTY, NONE, 0); 84 _(TIOCSETD, READ, sizeof(int)); 85 _(TIOCSPGRP, READ, pid_t_sz); 86 _(TIOCSTI, READ, sizeof(char)); 87 _(TIOCSWINSZ, READ, struct_winsize_sz); 88 89#if (SANITIZER_LINUX && !SANITIZER_ANDROID) 90 _(SIOCGETSGCNT, WRITE, struct_sioc_sg_req_sz); 91 _(SIOCGETVIFCNT, WRITE, struct_sioc_vif_req_sz); 92#endif 93 94#if SANITIZER_LINUX 95 // Conflicting request ids. 96 // _(CDROMAUDIOBUFSIZ, NONE, 0); 97 // _(SNDCTL_TMR_CONTINUE, NONE, 0); 98 // _(SNDCTL_TMR_START, NONE, 0); 99 // _(SNDCTL_TMR_STOP, NONE, 0); 100 // _(SOUND_MIXER_READ_LOUD, WRITE, sizeof(int)); // same as ...READ_ENHANCE 101 // _(SOUND_MIXER_READ_MUTE, WRITE, sizeof(int)); // same as ...READ_ENHANCE 102 // _(SOUND_MIXER_WRITE_LOUD, WRITE, sizeof(int)); // same as ...WRITE_ENHANCE 103 // _(SOUND_MIXER_WRITE_MUTE, WRITE, sizeof(int)); // same as ...WRITE_ENHANCE 104 _(BLKFLSBUF, NONE, 0); 105 _(BLKGETSIZE, WRITE, sizeof(uptr)); 106 _(BLKRAGET, WRITE, sizeof(int)); 107 _(BLKRASET, NONE, 0); 108 _(BLKROGET, WRITE, sizeof(int)); 109 _(BLKROSET, READ, sizeof(int)); 110 _(BLKRRPART, NONE, 0); 111 _(CDROMEJECT, NONE, 0); 112 _(CDROMEJECT_SW, NONE, 0); 113 _(CDROMMULTISESSION, WRITE, struct_cdrom_multisession_sz); 114 _(CDROMPAUSE, NONE, 0); 115 _(CDROMPLAYMSF, READ, struct_cdrom_msf_sz); 116 _(CDROMPLAYTRKIND, READ, struct_cdrom_ti_sz); 117 _(CDROMREADAUDIO, READ, struct_cdrom_read_audio_sz); 118 _(CDROMREADCOOKED, READ, struct_cdrom_msf_sz); 119 _(CDROMREADMODE1, READ, struct_cdrom_msf_sz); 120 _(CDROMREADMODE2, READ, struct_cdrom_msf_sz); 121 _(CDROMREADRAW, READ, struct_cdrom_msf_sz); 122 _(CDROMREADTOCENTRY, WRITE, struct_cdrom_tocentry_sz); 123 _(CDROMREADTOCHDR, WRITE, struct_cdrom_tochdr_sz); 124 _(CDROMRESET, NONE, 0); 125 _(CDROMRESUME, NONE, 0); 126 _(CDROMSEEK, READ, struct_cdrom_msf_sz); 127 _(CDROMSTART, NONE, 0); 128 _(CDROMSTOP, NONE, 0); 129 _(CDROMSUBCHNL, WRITE, struct_cdrom_subchnl_sz); 130 _(CDROMVOLCTRL, READ, struct_cdrom_volctrl_sz); 131 _(CDROMVOLREAD, WRITE, struct_cdrom_volctrl_sz); 132 _(CDROM_GET_UPC, WRITE, 8); 133 _(EVIOCGABS, WRITE, struct_input_absinfo_sz); // fixup 134 _(EVIOCGBIT, WRITE, struct_input_id_sz); // fixup 135 _(EVIOCGEFFECTS, WRITE, sizeof(int)); 136 _(EVIOCGID, WRITE, struct_input_id_sz); 137 _(EVIOCGKEY, WRITE, 0); 138 _(EVIOCGKEYCODE, WRITE, sizeof(int) * 2); 139 _(EVIOCGLED, WRITE, 0); 140 _(EVIOCGNAME, WRITE, 0); 141 _(EVIOCGPHYS, WRITE, 0); 142 _(EVIOCGRAB, READ, sizeof(int)); 143 _(EVIOCGREP, WRITE, sizeof(int) * 2); 144 _(EVIOCGSND, WRITE, 0); 145 _(EVIOCGSW, WRITE, 0); 146 _(EVIOCGUNIQ, WRITE, 0); 147 _(EVIOCGVERSION, WRITE, sizeof(int)); 148 _(EVIOCRMFF, READ, sizeof(int)); 149 _(EVIOCSABS, READ, struct_input_absinfo_sz); // fixup 150 _(EVIOCSFF, READ, struct_ff_effect_sz); 151 _(EVIOCSKEYCODE, READ, sizeof(int) * 2); 152 _(EVIOCSREP, READ, sizeof(int) * 2); 153 _(FDCLRPRM, NONE, 0); 154 _(FDDEFPRM, READ, struct_floppy_struct_sz); 155 _(FDFLUSH, NONE, 0); 156 _(FDFMTBEG, NONE, 0); 157 _(FDFMTEND, NONE, 0); 158 _(FDFMTTRK, READ, struct_format_descr_sz); 159 _(FDGETDRVPRM, WRITE, struct_floppy_drive_params_sz); 160 _(FDGETDRVSTAT, WRITE, struct_floppy_drive_struct_sz); 161 _(FDGETDRVTYP, WRITE, 16); 162 _(FDGETFDCSTAT, WRITE, struct_floppy_fdc_state_sz); 163 _(FDGETMAXERRS, WRITE, struct_floppy_max_errors_sz); 164 _(FDGETPRM, WRITE, struct_floppy_struct_sz); 165 _(FDMSGOFF, NONE, 0); 166 _(FDMSGON, NONE, 0); 167 _(FDPOLLDRVSTAT, WRITE, struct_floppy_drive_struct_sz); 168 _(FDRAWCMD, WRITE, struct_floppy_raw_cmd_sz); 169 _(FDRESET, NONE, 0); 170 _(FDSETDRVPRM, READ, struct_floppy_drive_params_sz); 171 _(FDSETEMSGTRESH, NONE, 0); 172 _(FDSETMAXERRS, READ, struct_floppy_max_errors_sz); 173 _(FDSETPRM, READ, struct_floppy_struct_sz); 174 _(FDTWADDLE, NONE, 0); 175 _(FDWERRORCLR, NONE, 0); 176 _(FDWERRORGET, WRITE, struct_floppy_write_errors_sz); 177 _(HDIO_DRIVE_CMD, WRITE, sizeof(int)); 178 _(HDIO_GETGEO, WRITE, struct_hd_geometry_sz); 179 _(HDIO_GET_32BIT, WRITE, sizeof(int)); 180 _(HDIO_GET_DMA, WRITE, sizeof(int)); 181 _(HDIO_GET_IDENTITY, WRITE, struct_hd_driveid_sz); 182 _(HDIO_GET_KEEPSETTINGS, WRITE, sizeof(int)); 183 _(HDIO_GET_MULTCOUNT, WRITE, sizeof(int)); 184 _(HDIO_GET_NOWERR, WRITE, sizeof(int)); 185 _(HDIO_GET_UNMASKINTR, WRITE, sizeof(int)); 186 _(HDIO_SET_32BIT, NONE, 0); 187 _(HDIO_SET_DMA, NONE, 0); 188 _(HDIO_SET_KEEPSETTINGS, NONE, 0); 189 _(HDIO_SET_MULTCOUNT, NONE, 0); 190 _(HDIO_SET_NOWERR, NONE, 0); 191 _(HDIO_SET_UNMASKINTR, NONE, 0); 192 _(MTIOCGET, WRITE, struct_mtget_sz); 193 _(MTIOCPOS, WRITE, struct_mtpos_sz); 194 _(MTIOCTOP, READ, struct_mtop_sz); 195 _(PPPIOCGASYNCMAP, WRITE, sizeof(int)); 196 _(PPPIOCGDEBUG, WRITE, sizeof(int)); 197 _(PPPIOCGFLAGS, WRITE, sizeof(int)); 198 _(PPPIOCGUNIT, WRITE, sizeof(int)); 199 _(PPPIOCGXASYNCMAP, WRITE, sizeof(int) * 8); 200 _(PPPIOCSASYNCMAP, READ, sizeof(int)); 201 _(PPPIOCSDEBUG, READ, sizeof(int)); 202 _(PPPIOCSFLAGS, READ, sizeof(int)); 203 _(PPPIOCSMAXCID, READ, sizeof(int)); 204 _(PPPIOCSMRU, READ, sizeof(int)); 205 _(PPPIOCSXASYNCMAP, READ, sizeof(int) * 8); 206 _(SIOCADDRT, READ, struct_rtentry_sz); 207 _(SIOCDARP, READ, struct_arpreq_sz); 208 _(SIOCDELRT, READ, struct_rtentry_sz); 209 _(SIOCDRARP, READ, struct_arpreq_sz); 210 _(SIOCGARP, WRITE, struct_arpreq_sz); 211 _(SIOCGIFENCAP, WRITE, sizeof(int)); 212 _(SIOCGIFHWADDR, WRITE, struct_ifreq_sz); 213 _(SIOCGIFMAP, WRITE, struct_ifreq_sz); 214 _(SIOCGIFMEM, WRITE, struct_ifreq_sz); 215 _(SIOCGIFNAME, NONE, 0); 216 _(SIOCGIFSLAVE, NONE, 0); 217 _(SIOCGRARP, WRITE, struct_arpreq_sz); 218 _(SIOCGSTAMP, WRITE, timeval_sz); 219 _(SIOCSARP, READ, struct_arpreq_sz); 220 _(SIOCSIFENCAP, READ, sizeof(int)); 221 _(SIOCSIFHWADDR, READ, struct_ifreq_sz); 222 _(SIOCSIFLINK, NONE, 0); 223 _(SIOCSIFMAP, READ, struct_ifreq_sz); 224 _(SIOCSIFMEM, READ, struct_ifreq_sz); 225 _(SIOCSIFSLAVE, NONE, 0); 226 _(SIOCSRARP, READ, struct_arpreq_sz); 227 _(SNDCTL_COPR_HALT, WRITE, struct_copr_debug_buf_sz); 228 _(SNDCTL_COPR_LOAD, READ, struct_copr_buffer_sz); 229 _(SNDCTL_COPR_RCODE, WRITE, struct_copr_debug_buf_sz); 230 _(SNDCTL_COPR_RCVMSG, WRITE, struct_copr_msg_sz); 231 _(SNDCTL_COPR_RDATA, WRITE, struct_copr_debug_buf_sz); 232 _(SNDCTL_COPR_RESET, NONE, 0); 233 _(SNDCTL_COPR_RUN, WRITE, struct_copr_debug_buf_sz); 234 _(SNDCTL_COPR_SENDMSG, READ, struct_copr_msg_sz); 235 _(SNDCTL_COPR_WCODE, READ, struct_copr_debug_buf_sz); 236 _(SNDCTL_COPR_WDATA, READ, struct_copr_debug_buf_sz); 237 _(SNDCTL_DSP_GETBLKSIZE, WRITE, sizeof(int)); 238 _(SNDCTL_DSP_GETFMTS, WRITE, sizeof(int)); 239 _(SNDCTL_DSP_NONBLOCK, NONE, 0); 240 _(SNDCTL_DSP_POST, NONE, 0); 241 _(SNDCTL_DSP_RESET, NONE, 0); 242 _(SNDCTL_DSP_SETFMT, WRITE, sizeof(int)); 243 _(SNDCTL_DSP_SETFRAGMENT, WRITE, sizeof(int)); 244 _(SNDCTL_DSP_SPEED, WRITE, sizeof(int)); 245 _(SNDCTL_DSP_STEREO, WRITE, sizeof(int)); 246 _(SNDCTL_DSP_SUBDIVIDE, WRITE, sizeof(int)); 247 _(SNDCTL_DSP_SYNC, NONE, 0); 248 _(SNDCTL_FM_4OP_ENABLE, READ, sizeof(int)); 249 _(SNDCTL_FM_LOAD_INSTR, READ, struct_sbi_instrument_sz); 250 _(SNDCTL_MIDI_INFO, WRITE, struct_midi_info_sz); 251 _(SNDCTL_MIDI_PRETIME, WRITE, sizeof(int)); 252 _(SNDCTL_SEQ_CTRLRATE, WRITE, sizeof(int)); 253 _(SNDCTL_SEQ_GETINCOUNT, WRITE, sizeof(int)); 254 _(SNDCTL_SEQ_GETOUTCOUNT, WRITE, sizeof(int)); 255 _(SNDCTL_SEQ_NRMIDIS, WRITE, sizeof(int)); 256 _(SNDCTL_SEQ_NRSYNTHS, WRITE, sizeof(int)); 257 _(SNDCTL_SEQ_OUTOFBAND, READ, struct_seq_event_rec_sz); 258 _(SNDCTL_SEQ_PANIC, NONE, 0); 259 _(SNDCTL_SEQ_PERCMODE, NONE, 0); 260 _(SNDCTL_SEQ_RESET, NONE, 0); 261 _(SNDCTL_SEQ_RESETSAMPLES, READ, sizeof(int)); 262 _(SNDCTL_SEQ_SYNC, NONE, 0); 263 _(SNDCTL_SEQ_TESTMIDI, READ, sizeof(int)); 264 _(SNDCTL_SEQ_THRESHOLD, READ, sizeof(int)); 265 _(SNDCTL_SYNTH_INFO, WRITE, struct_synth_info_sz); 266 _(SNDCTL_SYNTH_MEMAVL, WRITE, sizeof(int)); 267 _(SNDCTL_TMR_METRONOME, READ, sizeof(int)); 268 _(SNDCTL_TMR_SELECT, WRITE, sizeof(int)); 269 _(SNDCTL_TMR_SOURCE, WRITE, sizeof(int)); 270 _(SNDCTL_TMR_TEMPO, WRITE, sizeof(int)); 271 _(SNDCTL_TMR_TIMEBASE, WRITE, sizeof(int)); 272 _(SOUND_MIXER_READ_ALTPCM, WRITE, sizeof(int)); 273 _(SOUND_MIXER_READ_BASS, WRITE, sizeof(int)); 274 _(SOUND_MIXER_READ_CAPS, WRITE, sizeof(int)); 275 _(SOUND_MIXER_READ_CD, WRITE, sizeof(int)); 276 _(SOUND_MIXER_READ_DEVMASK, WRITE, sizeof(int)); 277 _(SOUND_MIXER_READ_ENHANCE, WRITE, sizeof(int)); 278 _(SOUND_MIXER_READ_IGAIN, WRITE, sizeof(int)); 279 _(SOUND_MIXER_READ_IMIX, WRITE, sizeof(int)); 280 _(SOUND_MIXER_READ_LINE, WRITE, sizeof(int)); 281 _(SOUND_MIXER_READ_LINE1, WRITE, sizeof(int)); 282 _(SOUND_MIXER_READ_LINE2, WRITE, sizeof(int)); 283 _(SOUND_MIXER_READ_LINE3, WRITE, sizeof(int)); 284 _(SOUND_MIXER_READ_MIC, WRITE, sizeof(int)); 285 _(SOUND_MIXER_READ_OGAIN, WRITE, sizeof(int)); 286 _(SOUND_MIXER_READ_PCM, WRITE, sizeof(int)); 287 _(SOUND_MIXER_READ_RECLEV, WRITE, sizeof(int)); 288 _(SOUND_MIXER_READ_RECMASK, WRITE, sizeof(int)); 289 _(SOUND_MIXER_READ_RECSRC, WRITE, sizeof(int)); 290 _(SOUND_MIXER_READ_SPEAKER, WRITE, sizeof(int)); 291 _(SOUND_MIXER_READ_STEREODEVS, WRITE, sizeof(int)); 292 _(SOUND_MIXER_READ_SYNTH, WRITE, sizeof(int)); 293 _(SOUND_MIXER_READ_TREBLE, WRITE, sizeof(int)); 294 _(SOUND_MIXER_READ_VOLUME, WRITE, sizeof(int)); 295 _(SOUND_MIXER_WRITE_ALTPCM, WRITE, sizeof(int)); 296 _(SOUND_MIXER_WRITE_BASS, WRITE, sizeof(int)); 297 _(SOUND_MIXER_WRITE_CD, WRITE, sizeof(int)); 298 _(SOUND_MIXER_WRITE_ENHANCE, WRITE, sizeof(int)); 299 _(SOUND_MIXER_WRITE_IGAIN, WRITE, sizeof(int)); 300 _(SOUND_MIXER_WRITE_IMIX, WRITE, sizeof(int)); 301 _(SOUND_MIXER_WRITE_LINE, WRITE, sizeof(int)); 302 _(SOUND_MIXER_WRITE_LINE1, WRITE, sizeof(int)); 303 _(SOUND_MIXER_WRITE_LINE2, WRITE, sizeof(int)); 304 _(SOUND_MIXER_WRITE_LINE3, WRITE, sizeof(int)); 305 _(SOUND_MIXER_WRITE_MIC, WRITE, sizeof(int)); 306 _(SOUND_MIXER_WRITE_OGAIN, WRITE, sizeof(int)); 307 _(SOUND_MIXER_WRITE_PCM, WRITE, sizeof(int)); 308 _(SOUND_MIXER_WRITE_RECLEV, WRITE, sizeof(int)); 309 _(SOUND_MIXER_WRITE_RECSRC, WRITE, sizeof(int)); 310 _(SOUND_MIXER_WRITE_SPEAKER, WRITE, sizeof(int)); 311 _(SOUND_MIXER_WRITE_SYNTH, WRITE, sizeof(int)); 312 _(SOUND_MIXER_WRITE_TREBLE, WRITE, sizeof(int)); 313 _(SOUND_MIXER_WRITE_VOLUME, WRITE, sizeof(int)); 314 _(SOUND_PCM_READ_BITS, WRITE, sizeof(int)); 315 _(SOUND_PCM_READ_CHANNELS, WRITE, sizeof(int)); 316 _(SOUND_PCM_READ_FILTER, WRITE, sizeof(int)); 317 _(SOUND_PCM_READ_RATE, WRITE, sizeof(int)); 318 _(SOUND_PCM_WRITE_CHANNELS, WRITE, sizeof(int)); 319 _(SOUND_PCM_WRITE_FILTER, WRITE, sizeof(int)); 320 _(TCFLSH, NONE, 0); 321 _(TCGETA, WRITE, struct_termio_sz); 322 _(TCGETS, WRITE, struct_termios_sz); 323 _(TCSBRK, NONE, 0); 324 _(TCSBRKP, NONE, 0); 325 _(TCSETA, READ, struct_termio_sz); 326 _(TCSETAF, READ, struct_termio_sz); 327 _(TCSETAW, READ, struct_termio_sz); 328 _(TCSETS, READ, struct_termios_sz); 329 _(TCSETSF, READ, struct_termios_sz); 330 _(TCSETSW, READ, struct_termios_sz); 331 _(TCXONC, NONE, 0); 332 _(TIOCGLCKTRMIOS, WRITE, struct_termios_sz); 333 _(TIOCGSOFTCAR, WRITE, sizeof(int)); 334 _(TIOCINQ, WRITE, sizeof(int)); 335 _(TIOCLINUX, READ, sizeof(char)); 336 _(TIOCSERCONFIG, NONE, 0); 337 _(TIOCSERGETLSR, WRITE, sizeof(int)); 338 _(TIOCSERGWILD, WRITE, sizeof(int)); 339 _(TIOCSERSWILD, READ, sizeof(int)); 340 _(TIOCSLCKTRMIOS, READ, struct_termios_sz); 341 _(TIOCSSOFTCAR, READ, sizeof(int)); 342 _(VT_ACTIVATE, NONE, 0); 343 _(VT_DISALLOCATE, NONE, 0); 344 _(VT_GETMODE, WRITE, struct_vt_mode_sz); 345 _(VT_GETSTATE, WRITE, struct_vt_stat_sz); 346 _(VT_OPENQRY, WRITE, sizeof(int)); 347 _(VT_RELDISP, NONE, 0); 348 _(VT_RESIZE, READ, struct_vt_sizes_sz); 349 _(VT_RESIZEX, READ, struct_vt_consize_sz); 350 _(VT_SENDSIG, NONE, 0); 351 _(VT_SETMODE, READ, struct_vt_mode_sz); 352 _(VT_WAITACTIVE, NONE, 0); 353#endif 354 355#if SANITIZER_LINUX && !SANITIZER_ANDROID 356 // _(SIOCDEVPLIP, WRITE, struct_ifreq_sz); // the same as EQL_ENSLAVE 357 _(CYGETDEFTHRESH, WRITE, sizeof(int)); 358 _(CYGETDEFTIMEOUT, WRITE, sizeof(int)); 359 _(CYGETMON, WRITE, struct_cyclades_monitor_sz); 360 _(CYGETTHRESH, WRITE, sizeof(int)); 361 _(CYGETTIMEOUT, WRITE, sizeof(int)); 362 _(CYSETDEFTHRESH, NONE, 0); 363 _(CYSETDEFTIMEOUT, NONE, 0); 364 _(CYSETTHRESH, NONE, 0); 365 _(CYSETTIMEOUT, NONE, 0); 366 _(EQL_EMANCIPATE, WRITE, struct_ifreq_sz); 367 _(EQL_ENSLAVE, WRITE, struct_ifreq_sz); 368 _(EQL_GETMASTRCFG, WRITE, struct_ifreq_sz); 369 _(EQL_GETSLAVECFG, WRITE, struct_ifreq_sz); 370 _(EQL_SETMASTRCFG, WRITE, struct_ifreq_sz); 371 _(EQL_SETSLAVECFG, WRITE, struct_ifreq_sz); 372 _(EVIOCGKEYCODE_V2, WRITE, struct_input_keymap_entry_sz); 373 _(EVIOCGPROP, WRITE, 0); 374 _(EVIOCSKEYCODE_V2, READ, struct_input_keymap_entry_sz); 375 _(FS_IOC_GETFLAGS, WRITE, sizeof(int)); 376 _(FS_IOC_GETVERSION, WRITE, sizeof(int)); 377 _(FS_IOC_SETFLAGS, READ, sizeof(int)); 378 _(FS_IOC_SETVERSION, READ, sizeof(int)); 379 _(GIO_CMAP, WRITE, 48); 380 _(GIO_FONT, WRITE, 8192); 381 _(GIO_SCRNMAP, WRITE, e_tabsz); 382 _(GIO_UNIMAP, WRITE, struct_unimapdesc_sz); 383 _(GIO_UNISCRNMAP, WRITE, sizeof(short) * e_tabsz); 384 _(KDADDIO, NONE, 0); 385 _(KDDELIO, NONE, 0); 386 _(KDDISABIO, NONE, 0); 387 _(KDENABIO, NONE, 0); 388 _(KDGETKEYCODE, WRITE, struct_kbkeycode_sz); 389 _(KDGETLED, WRITE, 1); 390 _(KDGETMODE, WRITE, sizeof(int)); 391 _(KDGKBDIACR, WRITE, struct_kbdiacrs_sz); 392 _(KDGKBENT, WRITE, struct_kbentry_sz); 393 _(KDGKBLED, WRITE, sizeof(int)); 394 _(KDGKBMETA, WRITE, sizeof(int)); 395 _(KDGKBMODE, WRITE, sizeof(int)); 396 _(KDGKBSENT, WRITE, struct_kbsentry_sz); 397 _(KDGKBTYPE, WRITE, 1); 398 _(KDMAPDISP, NONE, 0); 399 _(KDMKTONE, NONE, 0); 400 _(KDSETKEYCODE, READ, struct_kbkeycode_sz); 401 _(KDSETLED, NONE, 0); 402 _(KDSETMODE, NONE, 0); 403 _(KDSIGACCEPT, NONE, 0); 404 _(KDSKBDIACR, READ, struct_kbdiacrs_sz); 405 _(KDSKBENT, READ, struct_kbentry_sz); 406 _(KDSKBLED, NONE, 0); 407 _(KDSKBMETA, NONE, 0); 408 _(KDSKBMODE, NONE, 0); 409 _(KDSKBSENT, READ, struct_kbsentry_sz); 410 _(KDUNMAPDISP, NONE, 0); 411 _(KIOCSOUND, NONE, 0); 412 _(LPABORT, NONE, 0); 413 _(LPABORTOPEN, NONE, 0); 414 _(LPCAREFUL, NONE, 0); 415 _(LPCHAR, NONE, 0); 416 _(LPGETIRQ, WRITE, sizeof(int)); 417 _(LPGETSTATUS, WRITE, sizeof(int)); 418 _(LPRESET, NONE, 0); 419 _(LPSETIRQ, NONE, 0); 420 _(LPTIME, NONE, 0); 421 _(LPWAIT, NONE, 0); 422 _(MTIOCGETCONFIG, WRITE, struct_mtconfiginfo_sz); 423 _(MTIOCSETCONFIG, READ, struct_mtconfiginfo_sz); 424 _(PIO_CMAP, NONE, 0); 425 _(PIO_FONT, READ, 8192); 426 _(PIO_SCRNMAP, READ, e_tabsz); 427 _(PIO_UNIMAP, READ, struct_unimapdesc_sz); 428 _(PIO_UNIMAPCLR, READ, struct_unimapinit_sz); 429 _(PIO_UNISCRNMAP, READ, sizeof(short) * e_tabsz); 430 _(SCSI_IOCTL_PROBE_HOST, READ, sizeof(int)); 431 _(SCSI_IOCTL_TAGGED_DISABLE, NONE, 0); 432 _(SCSI_IOCTL_TAGGED_ENABLE, NONE, 0); 433 _(SNDCTL_DSP_GETISPACE, WRITE, struct_audio_buf_info_sz); 434 _(SNDCTL_DSP_GETOSPACE, WRITE, struct_audio_buf_info_sz); 435 _(TIOCGSERIAL, WRITE, struct_serial_struct_sz); 436 _(TIOCSERGETMULTI, WRITE, struct_serial_multiport_struct_sz); 437 _(TIOCSERSETMULTI, READ, struct_serial_multiport_struct_sz); 438 _(TIOCSSERIAL, READ, struct_serial_struct_sz); 439 440 // The following ioctl requests are shared between AX25, IPX, netrom and 441 // mrouted. 442 // _(SIOCAIPXITFCRT, READ, sizeof(char)); 443 // _(SIOCAX25GETUID, READ, struct_sockaddr_ax25_sz); 444 // _(SIOCNRGETPARMS, WRITE, struct_nr_parms_struct_sz); 445 // _(SIOCAIPXPRISLT, READ, sizeof(char)); 446 // _(SIOCNRSETPARMS, READ, struct_nr_parms_struct_sz); 447 // _(SIOCAX25ADDUID, READ, struct_sockaddr_ax25_sz); 448 // _(SIOCNRDECOBS, NONE, 0); 449 // _(SIOCAX25DELUID, READ, struct_sockaddr_ax25_sz); 450 // _(SIOCIPXCFGDATA, WRITE, struct_ipx_config_data_sz); 451 // _(SIOCAX25NOUID, READ, sizeof(int)); 452 // _(SIOCNRRTCTL, READ, sizeof(int)); 453 // _(SIOCAX25DIGCTL, READ, sizeof(int)); 454 // _(SIOCAX25GETPARMS, WRITE, struct_ax25_parms_struct_sz); 455 // _(SIOCAX25SETPARMS, READ, struct_ax25_parms_struct_sz); 456#endif 457#undef _ 458} 459 460static bool ioctl_initialized = false; 461 462struct ioctl_desc_compare { 463 bool operator()(const ioctl_desc& left, const ioctl_desc& right) const { 464 return left.req < right.req; 465 } 466}; 467 468static void ioctl_init() { 469 ioctl_table_fill(); 470 InternalSort(&ioctl_table, ioctl_table_size, ioctl_desc_compare()); 471 472 bool bad = false; 473 for (unsigned i = 0; i < ioctl_table_size - 1; ++i) { 474 if (ioctl_table[i].req >= ioctl_table[i + 1].req) { 475 Printf("Duplicate or unsorted ioctl request id %x >= %x (%s vs %s)\n", 476 ioctl_table[i].req, ioctl_table[i + 1].req, ioctl_table[i].name, 477 ioctl_table[i + 1].name); 478 bad = true; 479 } 480 } 481 482 if (bad) Die(); 483 484 ioctl_initialized = true; 485} 486 487// Handle the most evil ioctls that encode argument value as part of request id. 488static unsigned ioctl_request_fixup(unsigned req) { 489#if SANITIZER_LINUX 490 if ((req & ~0x3fff001fU) == IOCTL_EVIOCGBIT) 491 return IOCTL_EVIOCGBIT; 492 if ((req & ~0x3fU) == IOCTL_EVIOCGABS) 493 return IOCTL_EVIOCGABS; 494 if ((req & ~0x3fU) == IOCTL_EVIOCSABS) 495 return IOCTL_EVIOCSABS; 496#endif 497 return req; 498} 499 500static const ioctl_desc *ioctl_table_lookup(unsigned req) { 501 int left = 0; 502 int right = ioctl_table_size; 503 while (left < right) { 504 int mid = (left + right) / 2; 505 if (ioctl_table[mid].req < req) 506 left = mid + 1; 507 else 508 right = mid; 509 } 510 if (left == right && ioctl_table[left].req == req) 511 return ioctl_table + left; 512 else 513 return 0; 514} 515 516static const ioctl_desc *ioctl_lookup(unsigned req) { 517 req = ioctl_request_fixup(req); 518 const ioctl_desc *desc = ioctl_table_lookup(req); 519 if (desc) return desc; 520 521 // Try stripping access size from the request id. 522 desc = ioctl_table_lookup(req & ~0x3fff0000U); 523 // Sanity check: requests that encode access size are either read or write and 524 // have size of 0 in the table. 525 if (desc && desc->size == 0 && 526 (desc->type == ioctl_desc::WRITE || desc->type == ioctl_desc::READ)) 527 return desc; 528 return 0; 529} 530 531static void ioctl_common_pre(void *ctx, const ioctl_desc *desc, int d, 532 unsigned request, void *arg) { 533 if (desc->type == ioctl_desc::READ) { 534 unsigned size = desc->size ? desc->size : IOC_SIZE(request); 535 COMMON_INTERCEPTOR_READ_RANGE(ctx, arg, size); 536 } 537 if (desc->type != ioctl_desc::CUSTOM) 538 return; 539 switch (request) { 540 case 0x00008912: { // SIOCGIFCONF 541 struct __sanitizer_ifconf *ifc = (__sanitizer_ifconf *)arg; 542 COMMON_INTERCEPTOR_READ_RANGE(ctx, &ifc->ifc_len, sizeof(ifc->ifc_len)); 543 break; 544 } 545 } 546 return; 547} 548 549static void ioctl_common_post(void *ctx, const ioctl_desc *desc, int res, int d, 550 unsigned request, void *arg) { 551 if (desc->type == ioctl_desc::WRITE) { 552 // FIXME: add verbose output 553 unsigned size = desc->size ? desc->size : IOC_SIZE(request); 554 COMMON_INTERCEPTOR_WRITE_RANGE(ctx, arg, size); 555 } 556 if (desc->type != ioctl_desc::CUSTOM) 557 return; 558 switch (request) { 559 case 0x00008912: { // SIOCGIFCONF 560 struct __sanitizer_ifconf *ifc = (__sanitizer_ifconf *)arg; 561 COMMON_INTERCEPTOR_WRITE_RANGE(ctx, ifc->ifc_ifcu.ifcu_req, ifc->ifc_len); 562 break; 563 } 564 } 565 return; 566} 567